GoWM : Le Wasm Manager qui va Révolutionner tes Projets JavaScript
https://www.devbyben.fr/blog/gowm-le-wasm-manager-qui-va-revolutionner-tes-projets-javascript #javascript #webassembly #npm #opensource

GoWM : Le Wasm Manager qui va Révolutionner tes Projets JavaScript
https://www.devbyben.fr/blog/gowm-le-wasm-manager-qui-va-revolutionner-tes-projets-javascript #javascript #webassembly #npm #opensource
Are you reviewing your NPM dependancies for malicious code? #devsecops #appsec #npm
https://www.scworld.com/news/complex-npm-attack-uses-7-plus-layers-of-obfuscation-to-spread-pulsar-rat
Malicious #npm packages posing as utilities delete project directories
Hidden backdoors found in npm packages allow attackers to remotely wipe entire systems, raising serious supply chain security concerns.
Read: https://hackread.com/backdoors-npm-packages-attackers-wipe-systems/
#NPM: New Supply Chain #Malware Hits NPM and #PyPI Package Ecosystems. #ReactNative-Aria & #GlueStack packages with cumulative 1mln+ weekly downloads backdoored overnight - check your dependencies!
#SoftwareSupplyChainSecurity
https://thehackernews.com/2025/06/new-supply-chain-malware-operation-hits.html
New release of the Total-Serialism library for JavaScript with many bug fixes and updates is on github/npm!
https://github.com/tmhglnd/total-serialism/releases/tag/v2.10.2
https://www.npmjs.com/package/total-serialism
total-serialism is a set of functions used for procedurally generating and transforming number sequences (mainly in the form of arrays). This library does not output anything else then numbers, but can therefore be integrated with frameworks like P5js, ToneJS, Node4Max, Hydra and any other javascript based project you want to generate arrays for.
New: Backdoors found in Python & NPM packages targeting Windows & Linux! Attackers use fake ‘colorama’ & ‘colorizr’ to steal data + gain remote access.
Read more: https://hackread.com/backdoors-python-npm-packages-windows-linux/
Package lurking in npm for six years waits to destroy your work https://www.developer-tech.com/news/package-lurking-npm-six-years-waits-destroy-your-work/ #npm #developers #opensource #coding #programming #javascript #cybersecurity #malware #hacking #infosec #security #tech #news #technology
#NPM: Dozens of packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor:
https://www.bleepingcomputer.com/news/security/dozens-of-malicious-packages-on-npm-collect-host-and-network-data/
Dozens of malicious packages on #NPM collect host and network data
60 malicious npm packages caught mapping developer networks https://www.developer-tech.com/news/60-malicious-npm-packages-mapping-developer-networks/ #npm #javascript #developers #coding #programming #security #hacking #cybersecurity #infosec #malware #tech #news #technology
Malicious #NPM package uses Unicode #steganography to evade detection
#Development #Launches
ESLint can now lint HTML · The code linter delivers a new language plugin https://ilo.im/163v4b
_____
#ESLint #OpenSource #Coding #Linter #Parser #HTML #Npm #WebDev #Frontend
Malicious #npm Packages Infect 3,200+ #Cursor Users With Backdoor, Steal Credentials
https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html
#npm: Malicious npm Packages Infect 3,200+ #Cursor IDE Users With Backdoor, Steal Credentials:
https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html
Malicious #npm Packages Infect 3,200+ #Cursor Users With #Backdoor, Steal #Credentials
#Cybersecurity researchers have flagged 3 malicious npm packages that are designed to target the Apple #macOS version of Cursor
"Disguised as developer tools offering 'the cheapest Cursor API,' these packages steal user credentials, fetch an encrypted payload from threat actor-controlled infrastructure, overwrite Cursor's main.js file, & disable auto-updates to maintain persistence,"
https://thehackernews.com/2025/05/malicious-npm-packages-infect-3200.html
https://www.europesays.com/de/97674/ Remote-Access-Trojaner in npm-Paket mit 40.000 wöchentlichen Downloads gefunden #Deutschland #Germany #IT #JavaScript #npm #paketmanager #Python #Science #Science&Technology #Security #SoftwareSupplyChain #Softwareentwicklung #SupplyChainSecurity #Technik #Technology #Trojaner #Wissenschaft #Wissenschaft&Technik
Supply chain attack hits #npm package with 45,000 weekly downloads